Security researchers investigating multiple customer incidents in April 2025 found unauthorised file uploads and execution on SAP NetWeaver systems, with attackers placing JSP webshells in publicly accessible directories.
ERP Is Where Everything Already Is
An enterprise resource planning system holds the general ledger, the supplier master, the purchase orders, the payroll and the inventory positions. It is not a system that holds a copy of something — it is the system of record.
Access to it does not require lateral movement to become valuable. Payments can be redirected, suppliers created, inventory positions read. This desk filed ten months inside an unwatched ERP at 26-0620; this file is the same class of asset, reached through an internet-facing upload path.
A Webshell Is The Least Sophisticated Thing In This Database
It is a file that accepts commands over the web. The technique is decades old, requires no exploit development, and works whenever an attacker can write to a directory the web server will execute from.
That such a technique succeeds against a business-critical platform is the finding. The failure was architectural — a writable, executable, externally reachable path — rather than a matter of adversary capability.
And ERP Patching Is The Hardest Patching There Is
These systems are heavily customised, integrated with everything, and validated against business processes. An update is a project with testing cycles, not an overnight change, and downtime means the company cannot invoice or ship.
The result is estates that run behind by design, on the reasoning that they are internal systems. This file records what happens when that assumption stops being true. Graded medium: the technique and platform are consistently reported, the affected organisations are not named and the scale is not established.
Compiled from published vendor research, listed below. Affected organisations are not named and the number of incidents is not established. Corrections: corrections@forensicpost.com.